A few weeks ago, I decided to switch banks. Not really a big deal.
I’ve been a customer at a savings bank in the town where I grew up since I was eleven. For many years, that worked out just fine. But at some point, visiting the branch in person became increasingly impractical. Branches were consolidated, opening hours were reduced, and eventually the branch I used was only open a few days a week—and even then, only during limited time slots.
For someone who now lives over an hour away and works a normal full-time job, even the simplest banking task suddenly becomes a logistical challenge. So I decided to switch to a bank in my current place of residence. What followed was less a report on banking and more a journey through the contradictions of modern information security.
To schedule an appointment, I provided my cell phone number and a dedicated email address.
Not my default address, but one I created specifically for this purpose. For several years now, I’ve been using my own domain and assigning a unique email address for practically every service, every registration, and every provider. I have separate addresses for online stores, for insurance companies, for social media platforms—and, of course, for banks as well.
If an address is ever misused for spam, phishing, or other purposes, it’s very easy to trace which provider it was originally used with. Additionally, this approach makes many credential-stuffing attacks more difficult—attacks in which compromised login credentials are automatically tried on other platforms.
The employee recorded my information, made a copy of my ID card as a precaution, and explained that they could already start preparing a few things. After all, what you have, you have. At the time, I thought that was good service. Looking back, it was more of a first indication of just how automated some processes have become.
A few days later, I suddenly received a text message. It said my new debit card had now been activated for a mobile security procedure. A few seconds later, the same text message arrived again. The surprising thing was:
I hadn’t even opened an account yet.
I hadn’t signed any contract documents.
I hadn’t received any consultation.
I hadn’t made any decisions.
Nevertheless, apparently a debit card, a security procedure, and the processing of my registered cell phone number already existed. Of course, there must be some reasonable explanation for this.
Nevertheless, the question inevitably arose:
How many processes are actually already running with real customer data before the customer has even made a decision?
On the day of the appointment, I was informed that the employee in charge had unfortunately fallen ill. Another colleague would take over. That was perfectly fine. After a short wait, a young employee introduced himself to me. He was friendly, enthusiastic, and clearly eager to help. He was accompanied by a trainee who had only been with the company for a few days and was there to learn the ropes during the appointment. We entered the consultation room together. And there, two neatly prepared stacks of documents were already waiting on the table.
“We’ve prepared everything,” the advisor explained to me. “All you really need to do is sign.” That surprised me a bit. Up to that point, we hadn’t discussed different account options or conducted any kind of consultation. The account had already been selected. The card ordered. The paperwork prepared. The account switch scheduled. The actual consultation seemed to have already concluded before it hadeven begun. To be fair, I have to say: The consultant had actually guessed correctly. The selected account model matched exactly the one I myself had favored. Nevertheless , I was left with a strange impression. After all, normally the consultation should take place before the decision is made, not after.
But then one more thing occurred to him that he wanted to ask before I signed. “Do you actually work here?” He’d noticed the email address, which included the bank’s name, and wondered if that was really true. When I explained why I’d created that email address and that I work in cybersecurity, he replied, “Ah, I see. My father works in cybersecurity, too. I know quite a bit about that field myself.”
I just took that at face value.
The second stack of documents gave me much more to think about. It contained a wide variety of consent forms.
Advertising.
Data sharing.
Partner offers.
Insurance.
Analytical purposes.
Investment products.
And much more.My problem wasn’t that these consents existed. After all, I work in marketing myself. My problem was that the corresponding checkboxes were already checked. Not by me. But pre-selected by the system.
Without explanation.
Without asking.
Without any notice.
I therefore explained to the advisor that I wanted to remove all voluntary consents and that I did not consent to any of these data processing activities. He responded professionally and explained that this was not a problem. The settings would be adjusted retroactively and the documents reissued.
However, something else struck me as interesting.
How many people probably just sign such forms because they assume that the preselected options are already correct?
In my case, there’s another aspect to consider. As I mentioned earlier, I use a separate email address for nearly every provider. So if, in the future, an insurance provider, a financial partner, or any other company were to suddenly contact me using the exact email address created for this account opening, the source would be immediately traceable . Not based on an assumption, but because the address used already contains the original purpose in its name. The email address itself thus becomes an audit trail— a surprisingly simple yet effective tool for ensuring transparency regarding the use of one’s own data.
Now things got interesting. The actual account opening was complete. Next up was the account transfer service. And suddenly came the question that really made me suspicious.
“Whether I had my login credentials for my previous bank’s online banking.
‘They’ll need them now,’"
I had to pause for a moment to make sure I hadn’t misheard. After all, banks have been investing significant resources in awareness campaigns for years. They warn against phishing. Against social engineering. Against fake websites. Against fraudulent emails. Against manipulated text messages. And above all, with one phrase:
“Never share your login credentials.”
“Your bank will never ask you for your password.”
“Never share your TAN with third parties.”
Now I was sitting in a bank branch. And a bank employee was asking me for exactly those login credentials.
Because security awareness thrives on clear rules. And the rule about never sharing online banking login credentials is probably one of the most important ones of all. As soon as we start making exceptions, a simple rule suddenly becomes a case-by-case decision. And that’s exactly where many problems begin.
In information security, there’s a concept called a “trust boundary.” Put simply, it describes the point at which you leave an area you control and enter an area you can no longer control.
My own computer?
My area of responsibility.
My own operating system?
My area of responsibility.
My own browser?
My area of responsibility.
A computer that’s already been unlocked in a consultation room?
Absolutely not.
Even if I weren’t to enter the login credentials myself, but instead provided them to the employee for use during the handoff process, the same concern would remain: At that moment, I’m relinquishing control over highly sensitive login information. And that’s exactly what contradicts everything banks have been teaching their customers for years—and quite rightly so.
There was another problem as well. My current account still uses a traditional Chip-TAN method with a TAN generator. When I asked about it, I was told that this method is no longer offered at all. Even existing customers would be switched to the newer methods if their TAN generator malfunctioned.
Particularly noteworthy was an observation I made in the waiting area. Just a few minutes earlier, I’d overheard two older customers talking to a bank employee there. New smartphone. New app. Nothing worked anymore. Even the employee jokingly remarked that she wouldn’t replace her old phone for that reason alone. The irony was hard to miss.
We often discuss technical security. For many people, however, the biggest challenge is simply being able to use the security mechanisms at all.
I then explained that I’d like to use the manual switching service. To be honest, I’d assumed that a “switching service” actually had something to do with service. My wife had previously gone through a similar switch within the same banking group at another bank. There, direct debits, payment partners, and other processes were actively managed. The new bank contacted the old bank. At least, that was my expectation.
Instead, it turned out that the process ultimately boiled down to an online tool into which I was supposed to enter my login credentials for my previous bank. The advisor finally admitted openly that he himself had never actually carried out the manual switching service before. Completely legitimate. Nobody can know everything. So he decided to bring in an experienced colleague.
And this is exactly where the story became particularly interesting from a cybersecurity perspective:
The advisor stood up. So did the trainee. And both left the room. The computer remained unlocked. The internal applications remained open. My wife and I were left alone. For several minutes. Now my thoughts suddenly turned very technical.
USB keyloggers to record future keystrokes
HID attacks via devices such as Rubber Ducky or O.MG Cable
BadUSB attacks
Manipulation of local system settings
Persistence mechanisms for later access
Data theft via open applications
Access to internal information
Preparation for subsequent social engineering attacks
None of these scenarios require state actors, zero-day exploits, or Hollywood-style hackers.
Physical access. Unsecured USB ports. A few seconds. That’s often all it takes.
Of course, I didn’t do any of that.
But that’s not the crucial question.
The crucial question is:
What would have happened if someone with different intentions had been sitting there?
And another question came to mind:
Who’s to say that the bank itself is the only real target here?
After all, I was probably not the only one with this concern. If the planned bill-paying service actually requires regular access to existing online banking accounts at other institutions, I’m unlikely to be the only customer who’s expected to disclose their login credentials or authentication information in this room.
For an attacker, that would be an extremely attractive scenario.
Instead of attacking the bank itself, the real goal could be to record customers’ login credentials. A stealthy keylogger, a tampered USB device, or another mechanism for capturing keystrokes would then not only provide information about internal banking processes but also potentially grant direct access to end customers’ online banking accounts.
The damage would thus not be limited to the bank.
It would directly affect the people who entrust the bank with their most sensitive financial data.
And it was precisely this thought that made me feel significantly more uneasy at that moment than the idea of an attack on the bank itself.
A short time later, the advisor returned with a more experienced colleague. She was holding several old TAN generators in her hand. She suggested we could try it one more time. After all, the switch service was a central system of the savings banks and therefore secure. At that moment, I had to smile to myself. After all, I’d just been sitting unattended for several minutes at an unlocked workstation in the same room. I politely declined.
If I have to use login credentials or authentication methods, I’ll do it on my own computer. In my own environment. With my own TAN generator. As it turned out, the switch service was only accessible via a specific feature on the public website anyway. So I’d take care of it later at home.
When I left the branch, I had a new account.
What I also took home with me was an uneasy feeling. Not because of any individual employees. Not because of any ill intent. And not because I believe anyone there acted negligently. Quite the opposite. The advisor was friendly, dedicated, and eager to help. The colleague wanted to help. The trainee was there to learn. That’s exactly why I find this story so interesting.
Cybersecurity rarely fails due to a lack of knowledge. It rarely fails due to a lack of guidelines. It often fails because of routines, established processes, and the discrepancy between what we say about security and what we actually do in our day-to-day lives.
The bank sends the card and PIN separately for maximum security. It invests in authentication procedures, educational campaigns, and awareness initiatives against phishing and social engineering. At the same time, processes emerge in which customers are expected to disclose their online banking credentials in an environment they themselves can neither control nor assess.
RIEDEL Networks’ “Faule Aureden Quartet” hits the nail on the head once again with a few of its songs: You can order them here.
From an attacker’s perspective, this may even be more interesting than the actual bank’s workstation. After all, once someone gains access to end customers’ login credentials, they often no longer need to attack the bank at all. I found it at least as remarkable how casually highly sensitive information was discussed throughout the entire meeting: tax ID numbers, account details, powers of attorney, and personal financial information—all in the presence of a trainee who likely hadn’t been on the job for very long.
Don’t get me wrong: Of course young people need to learn, and of course every industry needs the next generation of talent. But information security doesn’t end with firewalls and antivirus systems. It starts with people. With confidentiality. And sometimes with the question of what information someone really needs to know.
After all, not every data breach starts with a hacker attack. Some begin simply with a single sentence that is later shared in a private setting, without the person telling the story even realizing what information they’re revealing.
I’m now particularly curious about the future of the email address I created specifically for opening this account. Maybe it will remain dormant forever. Maybe my skepticism was completely unfounded. And maybe I’ll never find out which of the pre-selected consents were actually removed. However, if an insurance agent, an investment advisor, or any other partner suddenly contacts me in the coming months, I’ll at least know exactly where my data came from. Because that’s exactly what this address is for. You could say it’s my personal security monitoring system for the analog world. Perhaps that’s the real takeaway from this visit to the bank.
Cybersecurity isn’t decided by glossy brochures, compliance manuals, or advertising campaigns. It’s decided in the small, everyday situations that no one questions anymore. Where security becomes uncomfortable for the first time. Where exceptions suddenly seem normal. And where you start to interpret your own rules a little more generously than those of others. Because sometimes the most interesting vulnerabilities aren’t found in technology. They’re found in the contradictions between what we preach and what we actually do.
*This article was created with the help of Copilot, taking current market events into account. The author, whose views are represented herein, was responsible for crafting the prompts and supervising the article.
From time to time, he gets the itch to explore things not just from a marketing perspective, but through his own unique lens. In doing so, he likes to use unconventional approaches to illustrate his point of view or spark reflection. One example worth mentioning here is the IT-SA 2024 advertising material exchange station.
His contributions deliberately straddle the line between expertise and humor—and invite readers to view even complex topics from an unusual perspective.
RIEDEL Networks is a privately held, global network provider focused on customized networks. We are listed in the Gartner Magic Quadrant for Global WAN Services as a niche provider specializing in mid-sized international companies and the media and events sectors. With our own global backbone, we help companies stay connected worldwide. Our services include Internet connectivity, MPLS, SD-WAN, SASE, Cloud Connect, security, and much more. Our customers come from a variety of industries and value quality, security, and reliability. RIEDEL Networks is a wholly owned subsidiary of the RIEDEL Communications Group in Wuppertal, Germany, and is privately owned by Thomas Riedel.